New BugSleep malware implant deployed in MuddyWater attacks

Share:

The Iranian-backed MuddyWater hacking group has partially switched to using a new custom-tailored malware implant to steal files and run commands on compromised systems.

Dubbed BugSleep, this new backdoor is still actively being developed and was discovered by analysts at Check Point Research while being distributed via well-crafted phishing lures.

The campaign pushes the malware via phishing emails disguised as invitations to webinars or online courses. The emails redirect the targets to archives containing malicious payloads hosted on the Egnyte secure file-sharing platform.

Some versions found in the wild also come with a custom malware loader designed to inject it into the active processes of a handful of apps, including Microsoft Edge, Google Chrome, AnyDesk, Microsoft OneDrive, PowerShell, and Opera.

“We discovered several versions of the malware being distributed, with differences between each version showing improvements and bug fixes (and sometimes creating new bugs),” Check Point said. “These updates, occurring within short intervals between samples, suggest a trial-and-error approach.”

With the switch to BugSleep, MuddyWater has switched from exclusively using legitimate Remote Management Tools (RMM) like Atera Agent and Screen Connect to maintain access to victims’ networks.

Attacks using this new malware focus on a wide range of targets worldwide, from government organizations and municipalities to airlines and media outlets, with targeting Israel and some in Turkey, Saudi Arabia, India, and Portugal.

​Exposed as Iranian intelligence agency hackers

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) was first seen in 2017. It is known for mainly targeting Middle Eastern entities (with a focus on Israeli targets) and continually upgrading its arsenal.

Although relatively new compared to other state-backed hacking groups, this Iranian threat group is highly active and targets many industry sectors, including telecommunications, government (IT services), and oil industry organizations.

Since it surfaced, it has slowly expanded its attacks to cyber-espionage campaigns against government and defense entities in Central and Southwest Asia, as well as organizations from North America, Europe, and Asia [1, 2, 3].

In January 2022, the U.S. Cyber Command (USCYBERCOM) officially linked MuddyWater to Iran’s Ministry of Intelligence and Security (MOIS), the country’s leading government intelligence agency.

One month later, U.S. and U.K. cybersecurity and law enforcement agencies exposed additional MuddyWater malware, a new Python backdoor dubbed Small Sieve deployed to maintain persistence and evade detection in compromised networks.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:20 am, Jun 19, 2025
weather icon 17°C
L: 15° | H: 18°
clear sky
Humidity: 83 %
Pressure: 1024 mb
Wind: 1 mph W
Wind Gust: 1 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 4%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 18°°C 0 mm 0% 10 mph 79 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 28°°C 0 mm 0% 11 mph 73 % 1025 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
18° | 32°°C 1 mm 100% 11 mph 73 % 1020 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
19° | 27°°C 0.8 mm 80% 13 mph 89 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
16° | 23°°C 0.36 mm 36% 14 mph 80 % 1015 mb 0 mm/h
Today 7:00 am
weather icon
17° | 18°°C 0 mm 0% 1 mph 79 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
23° | 26°°C 0 mm 0% 1 mph 59 % 1025 mb 0 mm/h
Today 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 2 mph 33 % 1024 mb 0 mm/h
Today 4:00 pm
weather icon
29° | 29°°C 0 mm 0% 8 mph 32 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 10 mph 41 % 1024 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 7 mph 56 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 7 mph 68 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 73 % 1024 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,360.15
-0.13%
Ethereum(ETH)
€2,194.38
0.02%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.88
0.04%
Solana(SOL)
€126.95
-1.44%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.148497
0.17%
Shiba Inu(SHIB)
€0.000010
-0.61%
Pepe(PEPE)
€0.000009
1.41%
Scroll to Top